Public report · Agent Readiness Audit
santosautomation.com
Agent-readiness score 100/100 · grade A · Transaction-ready · audited 2026-07-28
Scores
This report is cryptographically signed (HMAC-SHA256, signed 2026-07-28). Paste the JSON into the verifier to confirm it’s unmodified.
Findings
The service explicitly advertises machine commerce
Only advertise agent commerce when a real machine-payment or usage-billing interface exists.
The unpaid x402 challenge is machine-readable
Return a valid unpaid challenge without requiring a signature or transferring funds during discovery.
Price, billing unit, network, asset, and paid resource are consistent
Advertise canonical price, billing unit, network, asset, and paid resource.
Settlement and failure behavior is documented
Document settlement timing, failure behavior, receipts, and support escalation.
Retry or idempotency behavior is documented
Document retry, idempotency, and duplicate-payment behavior.
A vendor-specific capability manifest is machine-usable
Advertise a versioned capability description with inputs, outputs, cost, behavior, errors, limits, and docs.
Access requirements are documented
Document authentication or payment requirements, networks, and settlement behavior.
OpenAPI is explicitly advertised
Advertise the canonical OpenAPI URL from HTML, llms.txt, or HTTP Link metadata.
Operations have stable selection metadata
Add stable operationId values plus meaningful summaries, descriptions, and tags.
Requests and responses are machine-described
Describe typed inputs, outputs, examples, required fields, and non-2xx errors.
OpenAPI 3.1.0 is parseable
Publish parseable OpenAPI 3.x or Swagger 2.0 JSON/YAML with a canonical server.
robots.txt does not block known machine interfaces
Keep public machine documentation reachable and avoid accidental robots.txt blocking.
Machine-readable interfaces are advertised
Advertise canonical machine-readable interfaces from HTML or HTTP Link headers.
Public documentation is readable without interaction
Provide low-noise public documentation in static HTML, Markdown, or a typed interface description.
llms.txt follows the proposed structure
Use the proposed llms.txt structure: H1, useful summary, H2 link sections, and an Optional section when needed.
llms.txt is publicly reachable
Publish a concise /llms.txt that points to canonical machine interfaces.
llms.txt explains how agents should use the service
Explain capabilities, selection guidance, interfaces, pricing/access, limits, and support without overstating the proposal.
MCP is explicitly advertised
Advertise MCP through documentation, llms.txt, registry metadata, or an explicit endpoint link.
This check was not established within the bounded assessment
Document protected-resource and authorization discovery when authentication is required.
Official MCP Registry lookup was not enabled
Publish the server in the official MCP Registry when public distribution is intended.
This check was not established within the bounded assessment
Describe read-only, destructive, idempotent, and open-world behavior accurately.
This check was not established within the bounded assessment
Define outputSchema and return structuredContent with a compatible text fallback.
This check was not established within the bounded assessment
Expose deterministic tools with descriptions and strict input/output schemas.
MCP transport was not probed
Expose a standards-compatible MCP transport and negotiate a current stable protocol version.
The service publishes scope limitations
State limitations and avoid unsupported compliance or compatibility claims.
Provider or support information is published
Publish provider identity, support contact, version, status, and change information.
Errors or operational limits are documented
Document stable errors, retry guidance, timeouts, quotas, and rate limits.
The canonical interface uses HTTPS
Serve advertised interfaces and documentation over HTTPS.
Terms, privacy, or retention information is discoverable
Document terms, privacy, acceptable use, and retention where applicable.
Structured identity metadata is present
Publish consistent Organization, WebSite, Service, SoftwareApplication, or WebAPI identity metadata.
Machine-readable Offer pricing metadata is present
When paid access is advertised, publish consistent machine-readable Offer or pricing metadata.
JSON-LD blocks parse without remote context execution
Fix invalid JSON-LD syntax; remote contexts are not required for this check.
Schema.org WebAPI metadata is present
Describe the advertised API with Schema.org WebAPI or equivalent service metadata.
Pricing is consistent across the discovered public surfaces
Keep names, canonical URLs, prices, and interface claims consistent across public surfaces.
Embed the badge
Show the live score in your README. The badge updates on every re-audit and greys out when the report is older than 30 days.
[](https://www.santosautomation.com/reports/santosautomation.com)